PCNSA ยท Final Exam Prep
Final Exam Attack Plan
Domain weights, policy evaluation decision maps, security profile guide, NAT trap catalogue, IPsec VPN tree, 7-day protocol, and 20 rapid-recall cards.
| Domain | Weight | Priority | Key Focus Areas |
|---|---|---|---|
| D5 Network Protection | 28โ29% | ๐ด Highest | WildFire, SSL Decryption, GlobalProtect, IPsec VPN, Zone Protection |
| D4 Security & NAT Policies | 24% | ๐ด Highest | Rule order, NAT evaluation, DNAT/SNAT policy matching, U-Turn |
| D2 Networking | 18% | ๐ High | Interface types, Virtual Router, routing, HA, Zone Protection |
| D1 Device Management | 15โ16% | ๐ก Medium | Panorama, HA, upgrades, certificates, admin roles |
| D3 App-ID/User-ID/Profiles | 14% | ๐ก Medium | App-ID shift, User-ID zones, profile types and actions |
Four Unbreakable Rules:
- Policy rule order = top to bottom, first match wins (always)
- NAT is evaluated BEFORE security policy; post-NAT zone is used for policy matching
- Security profiles ONLY apply to Allow rules โ never Deny rules
- All changes require a Commit โ no exceptions, including password changes
Remember: Security profiles have NO effect on Deny rules. All profiles require SSL Decryption for HTTPS traffic inspection.
web-browsing โ HTTPS: 'web-browsing' = HTTP/TCP-80. 'ssl' = HTTPS. Allowing only 'web-browsing' does NOT allow HTTPS. Always include 'ssl' for HTTPS access.
App-ID reclassification: If a session is allowed as 'ssl' and reclassified to 'google-drive-web', the session is blocked if google-drive-web isn't allowed. Include dependent apps.
Profiles on Deny rules = useless: The most common trap. Attaching Antivirus/IPS/URL to a Deny rule = zero inspection. Only Allow rules execute profiles.
User-ID on untrust zone: NEVER. Attackers can spoof IP-to-user mappings from outside, bypassing user-based policies. Internal zones only.
WildFire = async delivery: Standard WildFire delivers the file THEN analyses. The file reaches the user before the verdict returns. WildFire Inline ML blocks synchronously.
No-Decrypt ABOVE Decrypt: Decryption policy is top-to-bottom. No-Decrypt rule for banking must be ABOVE the general Decrypt rule or it never matches.
IKE Phase 1 โ ONE mismatch = total failure: All parameters (encryption, hash, DH group, lifetime, IKE version) must match. SHA-256 โ SHA-1 = Phase 1 fails.
U-Turn NAT needs SNAT too: Without source NAT in U-Turn, the internal server replies directly to the client, causing a TCP session mismatch.
| Day | Focus | Activity |
|---|---|---|
| Day 7 | D5 Network Protection | WildFire, SSL Decryption, GlobalProtect, IPsec VPN โ heaviest weight domain |
| Day 6 | D4 Security & NAT Policies | NAT order, policy evaluation, U-Turn NAT, decryption policy |
| Day 5 | D2 Networking + D1 Device Mgmt | Interface types, Virtual Router, routing, HA, Panorama, certificates |
| Day 4 | D3 App-ID/User-ID/Profiles | App-ID shift scenarios, User-ID configuration, security profile actions |
| Day 3 | Mock Exam Set A | Full 40-question timed mock โ identify weak domains |
| Day 2 | Mock Exam Set B + Focused | Full mock B + focused practice on wrong questions from Set A |
| Day 1 | Exam Prep + Rapid Recall | Exam Prep (45 questions) + cheatsheet + flashcards โ then rest |